Every company is racing to deploy AI agents. Few are asking the security questions we'd insist on for any other new infrastructure.
Agents with tool/code access are a new privesc and RCE surface. Skipping sandboxing and isolation to ship faster is how this goes wrong.
#cyber
Hired a pentest firm. Day 1 ask: disable our ThreatLocker completely so they could get in.
Isn't getting past our defenses supposed to be the whole test?
Curious if this is normal for pentest firms or a red flag on them.
#cybersecurity#pentesting#ThreatLocker
A client's M365 account gets compromised. What do you do in the first hour — in what order, and why?
New checklist: contain → kill persistence (inbox rules, OAuth consents, added MFA) → investigate sign-in IPs → assess damage → notify → harden.
https://t.co/InbHVGczVS
A QR code in a fake HR email cost an employee her M365 credentials in minutes — no link, no attachment, just an image. It slipped past her email filtering entirely, since there was no text to scan.
Full story: https://t.co/Dc8s4VILQq
#cybersecurity#phishing
A QR code in a fake HR email cost an employee her M365 credentials in minutes — no link, no attachment, just an image. It slipped past her email filtering entirely, since there was no text to scan.
Full story: https://t.co/Dc8s4VILQq
#cybersecurity#phishing
After 20+ years in networking & cybersecurity, I built TransitPacket — free DNS, WHOIS, SSL & network tools for IT consultants and MSPs, plus practical guides. Still early — would love feedback on what's useful or missing.
https://t.co/NTyn1vfkGU
#MSP#cybersecurity#networking
After 20+ years in networking & cybersecurity, I built TransitPacket — free DNS, WHOIS, SSL & network tools for IT consultants and MSPs, plus practical guides. Still early — would love feedback on what's useful or missing.
https://t.co/NTyn1vfkGU
#MSP#cybersecurity#networking
everyone in a company panic when a security incident happens;
but after that, bosses start to take shortcuts to accomplish anything.
These shortcuts in security policies are ending taken down the entire network.
Why they always learn the hard way??
I called @WellsFargo to request a card replacement. To confirm my identity they asked me my Username from my online access.
Really? So my online credentials are available to all c service agents?
Horrible security practices!
Once again another small township in New Jersey @NJGov got a ransomware attack. Once again they paid the ransom.
And once again information is not disclosed.
This culture of silence only make all of us working on IT more vulnerable.
No one in State of New Jersey seem to care
Once again another small township in New Jersey @NJGov got a ransomware attack. Once again they paid the ransom.
And once again information is not disclosed.
This culture of silence only make all of us working on IT more vulnerable.
No one in State of New Jersey seem to care